Vulnerabilities/

PrismJS DOM Clobbering vulnerability

Severity:
Medium

Description

Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

Recommendation

Update the prismjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
prismjs
Anything's wrong? Let us know Last updated on June 30, 2025

This issue is available in SmartScanner Professional

See Pricing